This article details the recovery procedure for resolving a credential mismatch between the Identity Manager Provisioning Directory (IMPD) and the registry, which prevents the Identity Manager Provisioning Server (IMPS) service from starting.
Identity Manager 14.5
A mismatch between the password stored in the IMPD and the local registry file results in an authentication failure, characterized by LDAP_INVALID_CREDENTIALS errors in the etatrans log.
Perform these steps on all Provisioning Repository machines.
dxserver stop allC:\Program Files\CA\Directory\dxserver\config\settings\impd.dxc) and change set min-auth = clear-password; to set min-auth = none;.C:\Program Files\CA\Directory\dxserver\config\knowledge\ (e.g., *-impd-co.dxc, *-impd-main.dxc).auth-levels = clear-password to auth-levels = anonymous, clear-password.dxserver start alluserPassword value for the following entries:eTDSAContainerName=DSAs,eTNamespaceName=CommonObjects,dc=etadbeTDSAContainerName=DSAs,eTNamespaceName=CommonObjects,dc=im,dc=etadbPerform these steps on all machines hosting the Provisioning Server.
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\ComputerAssociates\Identity Manager\Provisioning Server\Domains\etaHKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\ComputerAssociates\Identity Manager\Provisioning Server\Domains\imeTPasswordDB key within both of the above paths.etatrans log indicates the system is using anonymous access.pwdmgr.exe), located typically at: c:\Program Files (x86)\CA\Identity Manager\Provisioning Server\bin\pwdmgr.exeeta and im domains.Perform these steps on all Provisioning Repository machines.
min-auth and auth-levels settings in the configuration and knowledge files (configured in Phase 1) back to clear-password.dxserver init allAlso please refer to the associated Knowledge Article - How to reset the Provisioning Repository password for IMPS on Linux
To speak with a customer representative or a Support Engineer see . Scroll to the bottom of the page and click on your respective region.